1 min read

Wyze Hit by Accidental Data Leak Affecting All Users

Silviu STAHIE

December 30, 2019

Promo Protect all your devices, without slowing them down.
Free 30-day trial
Wyze Hit by Accidental Data Leak Affecting All Users

Wyze, a company that makes smart home cameras and other IoT devices, revealed that one of their databases containing some of the user’s personal information was available online, exposing the sensitive data to anyone.

Wyze representatives admitted that one of their Elastic server that was set up for testing purposes and exposed personal details for their users. The leak included the customer emails along with camera nicknames, WiFi SSIDs, Wyze device information, body metrics for a small number of product beta testers, and limited tokens associated with Alexa integrations.

Companies use Elasticserch servers when they need to manage large databases, which makes querying and other operations faster. In the case of the Wyze leak, it turns out that one of the employees made a mistake when he set up the Elastic server, leaving it open and accessible to anyone.

“We copy some data from our main production servers and place it in a more flexible database that is easier to query. This new data table was protected when it was originally created,” said Dongsheng Song, co-founder of Wyze.

“However, a Wyze employee made a mistake on December 4 when they used this database and the previous security protocols for this data were removed. We are still investigating this event to find out why and how this happened.”

The company also complained about how they were notified of the problem and of how little time they had to fix the problem. They received a ticket on December 26, 9:21 a.m. PT about an article mentioning a massive data breach and in few hours issued pushed a token refresh to all Wyze users, which meant that everyone had to log in again as a precautionary method. Since Wyze is using a 2FA solution, some of the servers handling the request had a hard time keeping up.

For now, Wyze users don’t really have to do anything, because the user names, passwords, or financial information was not leaked. Customers will be receiving an email detailing the event and explanations as to what is going to happen next.

tags


Author


Silviu STAHIE

Silviu is a seasoned writer who followed the technology world for almost two decades, covering topics ranging from software to hardware and everything in between.

View all posts

You might also like

Bookmarks


loader